Summary of pornoxo.ws:443 (HTTPS) SSL Security Test
Provided "as is" without any warranty of any kind.
This test was made 1955 days ago and may be outdated
Refresh Test
Date/Time:Jun 3rd, 2021 20:59 GMT+0
Source IP/Port:145.239.1.155:443
Protocol:HTTPS
Location:Kassel, Germany
Your final score:
- A
- B
- C
- F
F
The SSL certificate is untrusted. Modern browsers will display a security warning message to all website visitors. Review and remediate highlighted issues.
Non-compliant with PCI DSS requirements
The server has TLS 1.0 enabled. It is non-compliant with NIST since SP 800-52 REV. 2 and non-compliant with PCI DSS since the 30th of June 2018.
Non-compliant with PCI DSS and NIST
The server has TLS 1.1 enabled. NIST recommends to drop TLS 1.1 support since SP 800-52 REV. 2
Information
Certificate chain relies on expired certificate, it can break connection for some clients.
Misconfiguration or weakness
Test Results Summary for pornoxo.ws
- 1 SSL/TLS end-entity certificate detected: the first certificate is an untrusted RSA 2048 bits certificate with issuer Go Daddy Secure Certificate Authority - G2 valid until April 28, 2021. 2 certificate chains detected. Show details.
- All 14 supported cipher suites are compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: secp256k1, P-384, P-521, P-256, K-283, B-283, K-409, B-409, K-571, B-571, brainpoolP256r1, brainpoolP384r1 and brainpoolP512r1. There is 1 more issue which makes the server non-compliant with PCI DSS: certificates are untrusted. Show details.
- 2 of 14 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: secp256k1, P-384, P-521, P-256, K-283, B-283, K-409, B-409, K-571, B-571, brainpoolP256r1, brainpoolP384r1 and brainpoolP512r1. There are 2 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, server does not support extended master sECret. Show details.
- 4 issues related to industry best practices were identified: server does not support TLS 1.3, server does not have cipher preference, server does not provide HSTS, certificate chain rely on expired certificate. Show details.
Compliance Summary for pornoxo.ws
- PCI DSS Compliance Failed: All 14 supported cipher suites are compliant with PCI DSS. The server supports PCI DSS compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with PCI DSS: secp256k1, P-384, P-521, P-256, K-283, B-283, K-409, B-409, K-571, B-571, brainpoolP256r1, brainpoolP384r1 and brainpoolP512r1. There is 1 more issue which makes the server non-compliant with PCI DSS: certificates are untrusted.
- HIPAA Compliance Failed: 2 of 14 supported cipher suites are not compliant with HIPAA requirements (Ref. NIST SP 800-52). The server supports HIPAA compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with HIPAA: secp256k1, P-384, P-521, P-256, K-283, B-283, K-409, B-409, K-571, B-571, brainpoolP256r1, brainpoolP384r1 and brainpoolP512r1. There are 2 more issues which make the server non-compliant with HIPAA: server does not support OCSP stapling, server does not support extended master sECret.
- GDPR Compliance Failed: All 14 supported cipher suites are compliant with GDPR. The server supports GDPR compliant protocols (TLSv1.1 and TLSv1.2) as well as non-compliant protocols (TLSv1.0). All supported elliptic curves are compliant with GDPR: secp256k1, P-384, P-521, P-256, K-283, B-283, K-409, B-409, K-571, B-571, brainpoolP256r1, brainpoolP384r1 and brainpoolP512r1. There is 1 more issue which makes the server non-compliant with GDPR: certificates are untrusted.